Executive brief
A vulnerability exists in the Linux kernel when the BPF Linux Security Module (LSM) is compiled in but not enabled at boot time. In this specific configuration, a privileged user can trigger a system crash (kernel panic) by creating certain types of data storage maps. This results in an immediate denial of service, impacting the availability of the affected server or device.
Technical details
A vulnerability exists in the Linux kernel's BPF subsystem due to improper initialization of BPF inode storage maps when CONFIG_BPF_LSM=y is set but the BPF LSM is not enabled via boot parameters. In this state, the BPF inode security blob offset remains uninitialized, causing bpf_inode() to calculate an incorrect memory offset that aliases the struct rcu_head.func callback pointer. When a privileged user updates or cleans up a BPF_MAP_TYPE_INODE_STORAGE map, the RCU callback pointer is overwritten with NULL, leading to a kernel panic when rcu_do_batch() attempts to execute the callback. The fix introduces a initialization flag to reject map allocation if the LSM framework has not successfully registered the BPF LSM.
Affected products
- Linux Linux 5.10 to 7.1.4, 7.2-rc2
Timeline
- 2026-06-28: disclosed: Initial patch submission by Matt Bobrowski
- 2026-06-30: patched: Patch committed to stable tree
- 2026-07-20: advisory: NVD publication date